Progress OpenEdge是一款应用程序。 Progress OpenEdge 11.7.14之前版本和12.x版本至12.2.9之前版本存在权限许可和访问控制问题漏洞,该漏洞源于OpenEdge应用程序中的某些SUID二进制文件容易受到特权升级的影响。本地攻击者利用该漏洞提升权限并破坏受影响的系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-24437 | 9.8 CRITICAL | Command Injection |
| CVE-2022-25767 | 9.8 CRITICAL | Remote Code Execution |
| CVE-2022-23923 | 8.6 HIGH | Sandbox Bypass |
| CVE-2022-25301 | 7.7 HIGH | Prototype Pollution |
| CVE-2022-25647 | 7.7 HIGH | Deserialization of Untrusted Data |
| CVE-2022-25850 | 7.5 HIGH | Server-side Request Forgery (SSRF) |
| CVE-2022-21144 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-22143 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-21227 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-21167 | 7.5 HIGH | Arbitrary Code Execution |
| CVE-2022-21189 | 7.3 HIGH | Prototype Pollution |
| CVE-2022-25842 | 6.9 MEDIUM | Arbitrary File Write via Archive Extraction (Zip Slip) |
| CVE-2022-25645 | 6.5 MEDIUM | Prototype Pollution |
| CVE-2022-26068 | 6.5 MEDIUM | Path Traversal |
| CVE-2022-21230 | 5.5 MEDIUM | Information Exposure |
| CVE-2022-25349 | 5.4 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2022-21149 | 5.4 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2022-25844 | 5.3 MEDIUM | Regular Expression Denial of Service (ReDoS) |
| CVE-2022-28481 | CSV-Safe gem 安全漏洞 | |
| CVE-2021-40822 | GeoServer 代码问题漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet